Skip to content

Axiom nonce reuse make axiom tracking difficult #2028

Description

@xrchz

Thm.mk_axiom_thm accepts a caller-supplied Nonce.t, but the nonce is neither consumed nor permanently bound to the axiom proposition. The same nonce can therefore introduce multiple unrelated propositions.

I am unsure whether this is best classified as a soundness issue or as an API/design issue, but as it stands there isn't a clean story for axiom tracking that one might have hoped for from Tag.

To see what I mean, consider running:

   open HolKernel;

   val n = Nonce.mk "ETA_AX";

   (* Register n for the genuine standard ETA axiom. *)
   val eta =
       Thm.mk_axiom_thm (n, Thm.concl boolTheory.ETA_AX);

   val _ = Theory.register_replayed_axiom eta;

   (* Reuse n for an unrelated proposition. *)
   val bad = Thm.mk_axiom_thm (n, boolSyntax.F);

This would enable:

  null (Thm.hyp bad);                    (* true *)
  Term.aconv (Thm.concl bad) boolSyntax.F;
  Tag.dest_tag (Thm.tag bad);            (* ([], ["ETA_AX"]) *)
  Theory.uptodate_thm bad;                (* true *)

Theory.current_axioms() also does not show the replayed-axiom registry.

I'm guessing with a name like "nonce" the intention for this mechanism was more to be actually one-shot, e.g.:

  1. Nonce.mk name creates a fresh nonce.
  2. The first mk_axiom_thm (n, proposition) atomically binds n to that proposition.
  3. Any later call to mk_axiom_thm with n fails.
  4. register_replayed_axiom verifies that the theorem's conclusion matches the proposition already bound to its nonce.
  5. Propagating the nonce through theorem tags remains unrestricted.

(Obviously, consumption should be thread-safe and should not be undone by Context.restore.)

Alternatively, mk_axiom_thm could accept (name, proposition) and mint the nonce internally.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions